Cross-site request forgery (CSRF) vulnerability in index.php in VigileCMS 1.4 allows remote attackers to change the admin password via certain parameters to the changepass module.Referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/38558https://www.exploit-db.com/exploits/4632http://www.securityfocus.com/bid/26484http://www.securityfocus.com/archive/1/483907/100/0/threaded